The package includes substantial documentation, tests, a changelog, and a clear license. Its small contributor base and absent security policy leave some maintenance and disclosure risk as the project matures.
78%
Total Score
67
88
75
The repository is owned by an individual rather than an organization, so the small maintainer and contributor base represents genuine continuity risk rather than normal organization publishing hygiene.
This is a young package, 38 days old with three releases and a median interval of about 1.4 days. The rapid early cadence is encouraging, but there is not yet enough history to demonstrate long-term maintenance.
Two contributors are active, with the leading contributor responsible for about 60% of recent commits. That is a small team and creates some continuity risk, but activity is not concentrated in one contributor alone.
No security policy is present in the repository. This is a transparency gap for reporting vulnerabilities, although it does not by itself indicate unsafe code.
Version v0.5.2 is not a stable-major release, so the API may still change before a 1.0 release. It is not marked as a prerelease, which partly offsets the maturity concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0 || ^5.0 | — | — |
livewire/livewire Version ^3.0 || ^4.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.